I can't find this mentioned in the docs - should Enhanced Filtering for Connectors be enabled for the HEC connectors in Exchange Online?
On the receiving end we always see SPF fail when the last external IP is Check Point:
spf=softfail (sender IP is 52.212.19.177) smtp.mailfrom=dell.com; dkim=fail (signature did not verify) header.d=dell.com;dmarc=fail action=oreject header.from=dell.com;compauth=none reason=452
... which I assume is to be expected as we do not have skip listing enabled at https://security.microsoft.com/skiplisting?